Protect the security of IIS server accounts

Source: Internet
Author: User

After learning about IIS server, we also need to know a lot about ISS. Windows Server 2003 has a large number of built-in user accounts which cannot be deleted but can be renamed. The two most common accounts in Windows 2003 are Guest and Administrator.

By default, the Guest account is disabled on the member server and domain controller. This setting should not be changed. The Built-in Administrator account should be renamed and its description should be changed to prevent attackers from damaging the remote server through this account.

Many variants of malicious code attempt to use a built-in Administrator Account to destroy an IIS server. In recent years, the significance of the above-mentioned rename configuration has been greatly reduced because many new attack tools have emerged, which attempt to specify the security identifier (SID) of the Built-in Administrator account) to determine the real name of the account, thus encroaching on the server.

SID is the unique value that can determine each user, group, computer account, and logon session in the network. It is impossible to change the SID of the built-in account. Change the local administrator account to a special name, so that your operations can monitor attack attempts on this account.

• To protect the security of all accounts on the IIS server, perform the following steps:

1. Rename the Administrator and Guest accounts, and change the password on each domain and server to a long and complex value.

2. Use different names and passwords on each server. If the same account name and password are used on all domains and servers, the attacker can access all other servers with the same account name and password by obtaining access permissions to one Member Server.

3. Change the default account description to prevent accounts from being easily identified.

4. record these changes to a secure location.

Note: You can rename the Built-in Administrator account using the Group Policy. This setting is not configured in any security template provided in this Guide, because you must select a unique name for your environment. "Account: Rename Administrator Account" can be used to Rename Administrator accounts in three environments defined in this Guide. This setting is part of the security option settings of the Group Policy.

Let's talk about how to protect the security knowledge of IIS servers first.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.